Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

asynchronous revocation check would be far superior option; I'm sad industry abandoned trying to make it work.




The article does link in multiple places to another article discussing why revocation checks do not work for privacy (you're telling someone your browsing history basically) and reliability (what if the CA's revocation checker goes down?) reasons.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: